CVE-2025-52644

MEDIUM

HCL AION is affected by a vulnerability where certain user actions are not adequately audited or logged.

Title source: cna
STIX 2.1

Description

HCL AION is affected by a vulnerability where certain user actions are not adequately audited or logged. The absence of proper auditing mechanisms may reduce traceability of user activities and could potentially impact monitoring, accountability, or incident investigation processes.

Scores

CVSS v3 5.8
EPSS 0.0005
EPSS Percentile 14.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-778
Status published
Products (2)
HCL/AION 2.0
hcltech/aion 2.0 - 2.1.2
Published Mar 16, 2026
Tracked Since Mar 16, 2026